Back to skill

Security audit

remote-chrome

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it says, but it exposes remote browser control and VNC passwords in ways that need careful review before installation.

Install only on an isolated or trusted host. Treat the VNC password and generated noVNC URL as secrets, avoid sharing terminal output, do not expose ports 5900, 6080, or 9222 to untrusted networks, prefer localhost binding with SSH/VPN tunneling, and avoid running the scripts as root until the password storage and process cleanup are hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
start-remote-chrome.sh:307
Finding

Remote desktop services are exposed over plaintext connections and leak credentials in URLs

Content
View full analysis
/dev/null 2>&1 ``` ```bash if [[ "$NOVNC_LAUNCHER" == *"launch.sh"* ]]; then $NOVNC_LAUNCHER --vnc localhost:${VNC_PORT} --listen ${NOVNC_PORT} >/dev/null 2>&1 & elif [[ "$NOVNC_LAUNCHER" == *"novnc_proxy"* ]]; then $NOVNC_LAUNCHER --vnc localhost:${VNC_PORT} --listen ${NOVNC_PORT} >/dev/null 2>&1 & else # Use websockify $NOVNC_LAUNCHER --web /usr/share/novnc localhost:${NOVNC_PORT} localhost:${VNC_PORT} >/dev/null 2>&1 & fi ``` ```bash echo -e " ${CYAN}${BOLD}http://${HOST_IP}:${NOVNC_PORT}/vnc.html?host=${HOST_IP}&port=${NOVNC_PORT}&password=${VNC_PASSWORD}&autoconnect=true${NC}" echo "" log_info "${BOLD}💻 Or connect via VNC client:${NC}" echo -e " ${CYAN}${BOLD}${HOST_IP}:${VNC_PORT}${NC} ${YELLOW}(Password: ${VNC_PASSWORD})${NC}" echo "" log_info "${BOLD}🔑 VNC Password: ${CYAN}${BOLD}${VNC_PASSWORD}${NC}" ``` The documentation also explicitly recommends opening all relevant ports: ```bash sudo ufw allow 5900/tcp sudo ufw allow 6080/tcp sudo ufw allow 9222/tcp ``` ### Technical Analysis The x11vnc and noVNC commands do not explicitly restrict their listening sockets to the loopback interface. Depending on the tools' defaults, they may listen on all network interfaces. The documentation reinforces broad network exposure by instructing users to open the VNC, noVNC, and Chrome debugging ports in the firewall. The recommended noVNC URL uses plaintext HTTP and includes the VNC password as a query parameter. Query-string credentials can be retained in shell logs, terminal captures, browser history, bookmarks, monitoring systems, screenshots, copie ...[truncated 1270 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
start-remote-chrome.sh:305
Finding

Predictable temporary password file allows symlink-based file overwrite

Content
View full analysis
/tmp/remote-chrome-vnc-password.txt chmod 600 /tmp/remote-chrome-vnc-password.txt ``` ### Technical Analysis The script stores the password at a fixed, predictable path in the shared `/tmp` directory. Shell redirection opens the destination before `chmod 600` is applied and follows symbolic links. A local attacker can create `/tmp/remote-chrome-vnc-password.txt` as a symbolic link to another file before a more privileged user starts the service. If the launching account can write the linked target, the redirection overwrites it with the generated password. The subsequent `chmod` may also change the target file's permissions. The fixed path additionally causes collisions between multiple users or service instances. ### Attack Path 1. A local attacker predicts the fixed pathname `/tmp/remote-chrome-vnc-password.txt`. 2. Before a privileged user launches the service, the attacker creates that path as a symbolic link to a target file writable by the launching account. 3. The privileged user runs `start-remote-chrome.sh`. 4. Shell redirection follows the symbolic link and replaces the target file's contents with the generated VNC password. 5. The script then applies mode `600`, potentially changing the target file's permissions as well. 6. The overwritten file may cause configuration corruption, denial of service, or security-control failure. ### Impact Assessment The direct capability is arbitrary file overwrite within the permissions of the account running the script. If run as root, this can affect root-writable files, subject to operating-system symlink protections and the semantics of the selected target. Exploitation can cau ...[truncated 225 chars]
Remediation
View remediation
"$password_file" ``` 4. Do not reuse a globally predictable pathname. 5. Refuse to operate if the destination is a symbolic link or is not owned by the current user. 6. Store the selected password-file path in a protected PID/state file so the status and stop scripts can find the correct instance. 7. Avoid recommending or requiring execution as root. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
start-remote-chrome.sh:305
Finding

VNC password is exposed through process arguments and command output

Content
View full analysis
/tmp/remote-chrome-vnc-password.txt chmod 600 /tmp/remote-chrome-vnc-password.txt x11vnc -display :${DISPLAY_NUM} -forever -shared -rfbport ${VNC_PORT} -passwd ${VNC_PASSWORD} -bg -o /tmp/x11vnc.log >/dev/null 2>&1 ``` ```bash echo -e " ${CYAN}${BOLD}http://${HOST_IP}:${NOVNC_PORT}/vnc.html?host=${HOST_IP}&port=${NOVNC_PORT}&password=${VNC_PASSWORD}&autoconnect=true${NC}" echo "" log_info "${BOLD}💻 Or connect via VNC client:${NC}" echo -e " ${CYAN}${BOLD}${HOST_IP}:${VNC_PORT}${NC} ${YELLOW}(Password: ${VNC_PASSWORD})${NC}" echo "" log_info "${BOLD}🔑 VNC Password: ${CYAN}${BOLD}${VNC_PASSWORD}${NC}" ``` The status script redisplays the same credential: ```bash VNC_PASSWORD="" if [ -f /tmp/remote-chrome-vnc-password.txt ]; then VNC_PASSWORD=$(cat /tmp/remote-chrome-vnc-password.txt 2>/dev/null) fi ``` ```bash echo -e " ${CYAN}${BOLD}http://${HOST_IP}:${NOVNC_PORT}/vnc.html?host=${HOST_IP}&port=${NOVNC_PORT}&password=${VNC_PASSWORD}&autoconnect=true${NC}" echo "" echo -e "${BOLD}💻 VNC Client Connection:${NC}" echo -e " ${CYAN}${BOLD}${HOST_IP}:${VNC_PORT}${NC} ${YELLOW}(Password: ${VNC_PASSWORD})${NC}" echo "" echo -e "${BOLD}🔑 VNC Password: ${CYAN}${BOLD}${VNC_PASSWORD}${NC}" ``` ### Technical Analysis The `-passwd` argument places the VNC password directly in the x11vnc command line. Depending on operating-system process visibility controls, command-line arguments may be visible to other local users, process-monitoring agents, diagnostic tools, or logs. The start and status scripts also print the password in plaintext and embed it in a URL. Consequently, the credential can be captured by terminal logging, automation logs, support bundles, screenshots, browser history, or copied co ...[truncated 995 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
start-remote-chrome.sh:269
Finding

Broad pattern-based process termination can kill unrelated workloads

Content
View full analysis
/dev/null || true pkill -f "websockify.*${NOVNC_PORT}" 2>/dev/null || true pkill -f "novnc_proxy.*${NOVNC_PORT}" 2>/dev/null || true pkill -f "Xvfb :${DISPLAY_NUM}" 2>/dev/null || true pkill -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null || true log_info "${GREEN}✓ Services stopped${NC}" } ``` The stop script repeats these broad matches and uses forceful termination for Chrome: ```bash if [ -n "$CHROME_PID" ]; then kill $CHROME_PID 2>/dev/null && echo -e "${GREEN}✓ Chrome stopped${NC}" # Wait for Chrome to exit gracefully sleep 2 # If still running, force kill all related processes pkill -9 -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null fi ``` ```bash pkill -f "x11vnc.*:${DISPLAY_NUM}" 2>/dev/null pkill -f "websockify.*${NOVNC_PORT}" 2>/dev/null pkill -f "novnc_proxy.*${NOVNC_PORT}" 2>/dev/null pkill -f "Xvfb :${DISPLAY_NUM}" 2>/dev/null pkill -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null ``` ### Technical Analysis The scripts do not retain and validate a complete set of launcher-owned process identifiers. Instead, they terminate every process whose command line matches a display number, port, or browser argument. These patterns are not unique ownership identifiers. An unrelated Xvfb, browser, noVNC, or websockify instance can legitimately share the same display number or port text. The start operation invokes cleanup before launching new processes, so merely starting this Skill can terminate pre-existing workloads. Use of `pkill -9` is especially hazardous because it prevents graceful shutdown and ...[truncated 1002 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
start-remote-chrome.sh:36
Finding

Unvalidated option values permit argument injection into launched services

Content
View full analysis
/dev/null 2>&1 & ``` ```bash x11vnc -display :${DISPLAY_NUM} -forever -shared -rfbport ${VNC_PORT} -passwd ${VNC_PASSWORD} -bg -o /tmp/x11vnc.log >/dev/null 2>&1 ``` Proxy values are assembled into a space-separated string and expanded unquoted: ```bash CHROME_PROXY_ARGS="" if [ -n "$HTTP_PROXY" ]; then PROXY_MSG=" (using proxy: ${HTTP_PROXY})" CHROME_PROXY_ARGS="--proxy-server=${HTTP_PROXY}" if [ -n "$NO_PROXY" ]; then CHROME_PROXY_ARGS="${CHROME_PROXY_ARGS} --proxy-bypass-list=${NO_PROXY}" fi fi ``` ```bash DISPLAY=:${DISPLAY_NUM} ${CHROME_BIN} \ --remote-debugging-port=${CHROME_DEBUG_PORT} \ --disable-gpu \ --disable-dev-shm-usage \ $CHROME_PROXY_ARGS \ --window-size=${SCREEN_WIDTH},${SCREEN_HEIGHT} \ --start-maximized \ --disable-infobars \ --disable-extensions \ about:blank >/dev/null 2>&1 & ``` ### Technical Analysis Port values are not validated as numeric values in the range `1` through `65535`, screen dimensions are not checked against the documented format, and proxy-related values are not structurally validated. Because these variables are expanded w ...[truncated 1735 chars]
Remediation
View remediation
= 1 && VNC_PORT <= 65535 )) || exit 1 ``` 2. Validate screen sizes against a strict allowlist or pattern: ```bash [[ "$SCREEN_SIZE" =~ ^[0-9]{2,5}x[0-9]{2,5}x(24|32)$ ]] || exit 1 ``` 3. Apply reasonable maximum width and height limits to prevent resource exhaustion. 4. Parse and validate proxy URLs with an approved scheme and valid host/port structure. 5. Validate bypass entries individually rather than accepting arbitrary whitespace-separated content. 6. Build all commands with Bash arrays: ```bash chrome_args=( "--remote-debugging-port=$CHROME_DEBUG_PORT" "--disable-gpu" "--window-size=${SCREEN_WIDTH},${SCREEN_HEIGHT}" ) [[ -n "$HTTP_PROXY" ]] && chrome_args+=("--proxy-server=$HTTP_PROXY") [[ -n "$NO_PROXY" ]] && chrome_args+=("--proxy-bypass-list=$NO_PROXY") DISPLAY=":$DISPLAY_NUM" "$CHROME_BIN" "${chrome_args[@]}" about:blank ``` 7. Quote every scalar expansion and use `--` where the called utility supports end-of-options markers. 8. Do not forward untrusted natural-language or remote input directly into these command-line options. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior includes exposing and inspecting a Chrome remote debugging interface, listing open tabs, and surfacing access details such as VNC password, which materially expands the security impact beyond simple service lifecycle management. This mismatch can mislead users and reviewers, causing them to approve a skill that provides remote control and sensitive browser introspection capabilities they did not fully expect.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

Documenting storage of the VNC password in a predictable file under /tmp increases the risk of credential disclosure through local information leaks, symlink/race issues, or accidental exposure by other tooling. While mode 600 helps, /tmp is a shared, high-risk location and the password is part of a service intended for remote access.

Content

Scanner excerpt · references/configuration.md (reported line 178)May include surrounding context.

md
## File Locations

### Password Storage
- **Location**: `/tmp/remote-chrome-vnc-password.txt`
- **Permissions**: `600` (owner read/write only)
- **Lifecycle**: Created on start, deleted on stop
- **Purpose**: Allows status script to retrieve VNC password

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

This troubleshooting guidance reinforces the existence of a persistent plaintext VNC password file in /tmp, which normalizes insecure credential handling for a remotely accessible service. In the context of noVNC/VNC exposure, compromise of that file can directly grant GUI access to the browser session.

Content

Scanner excerpt · references/configuration.md (reported line 282)May include surrounding context.

md
- Ensure noVNC files are installed in `/usr/share/novnc/`

### Cannot Retrieve VNC Password
- Check if `/tmp/remote-chrome-vnc-password.txt` exists
- Verify file permissions
- Restart the service to regenerate password file

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly display a remotely reachable noVNC URL, VNC connection details, and a plaintext VNC password, normalizing exposure of sensitive access credentials in output without any warning. In the context of a remote-browser skill, this is especially dangerous because anyone who can view logs, transcripts, screenshots, or terminal history may gain interactive GUI access to the browser session and potentially the user's authenticated web activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The status example advertises a Chrome remote debugging endpoint as accessible via a remote host URL, but provides no warning that DevTools remote debugging can permit powerful browser inspection and control. In a remote Chrome service, exposing this endpoint beyond localhost can enable session hijacking, cookie/token theft, page interaction, and broader browser compromise by anyone who can reach it.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The script stores the generated VNC password in plaintext at a predictable path under /tmp so another component can read it later. In a shared or multi-user environment, predictable credential files increase the attack surface and may expose access secrets through filesystem mishandling or incomplete cleanup.

Content

Scanner excerpt · start-remote-chrome.sh (reported line 305)May include surrounding context.

sh
# 2. Start x11vnc server
log_info "${YELLOW}• Starting x11vnc (port ${VNC_PORT})...${NC}"
# Save password to file for status script to read
echo "${VNC_PASSWORD}" > /tmp/remote-chrome-vnc-password.txt
chmod 600 /tmp/remote-chrome-vnc-password.txt
x11vnc -display :${DISPLAY_NUM} -forever -shared -rfbport ${VNC_PORT} -passwd ${VNC_PASSWORD} -bg -o /tmp/x11vnc.log >/dev/null 2>&1
sleep 2

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script reads the VNC password from a plaintext file and prints it directly to stdout, and also embeds it into a noVNC access URL. This exposes credentials through terminal history, logs, screenshots, shell capture, and any tooling that records command output, making unauthorized access to the remote desktop much easier.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Reading a VNC password from /tmp/remote-chrome-vnc-password.txt indicates credential material is stored in a predictable temporary-file location. Even before it is printed, storing secrets in /tmp increases the risk of accidental exposure, weak permissions, race conditions, or access by other local users/processes depending on how the file is created.

Content

Scanner excerpt · status-remote-chrome.sh (reported line 259)May include surrounding context.

sh
# Get VNC password from password file
    VNC_PASSWORD=""
    if [ -f /tmp/remote-chrome-vnc-password.txt ]; then
        VNC_PASSWORD=$(cat /tmp/remote-chrome-vnc-password.txt 2>/dev/null)
    fi

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The script loads a plaintext password from a predictable file path into a shell variable, contributing to credential handling risk and enabling subsequent disclosure elsewhere in the script. In this skill's context, the status command is not merely administrative; it becomes a credential retrieval mechanism for the remote desktop service.

Content

Scanner excerpt · status-remote-chrome.sh (reported line 260)May include surrounding context.

sh
# Get VNC password from password file
    VNC_PASSWORD=""
    if [ -f /tmp/remote-chrome-vnc-password.txt ]; then
        VNC_PASSWORD=$(cat /tmp/remote-chrome-vnc-password.txt 2>/dev/null)
    fi

    # Display access information

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly discloses the VNC password and places it into the printed noVNC URL as a query parameter. Query parameters are especially risky because they are often captured by browser history, reverse proxies, analytics, clipboard managers, and logs, turning a local secret into a broadly exposed credential.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · start-remote-chrome.sh (reported line 306)May include surrounding context.

sh
pkill -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null

# Clean up password file
rm -f /tmp/remote-chrome-vnc-password.txt 2>/dev/null

echo ""
echo -e "${GREEN}${BOLD}✓ Service stopped${NC}"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · stop-remote-chrome.sh (reported line 76)May include surrounding context.

sh
pkill -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null

# Clean up password file
rm -f /tmp/remote-chrome-vnc-password.txt 2>/dev/null

echo ""
echo -e "${GREEN}${BOLD}✓ Service stopped${NC}"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · stop-remote-chrome.sh (reported line 76)May include surrounding context.

sh
pkill -f "${CHROME_BIN}.*--display=:${DISPLAY_NUM}" 2>/dev/null

# Clean up password file
rm -f /tmp/remote-chrome-vnc-password.txt 2>/dev/null

echo ""
echo -e "${GREEN}${BOLD}✓ Service stopped${NC}"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents direct shell-script execution but does not declare any tool scope or allowed-tools, which weakens policy enforcement and makes it harder for a caller or platform to constrain what the skill may run. In a skill that starts network-exposed services and interacts with local processes, missing explicit permissions increases the chance of unintended or over-broad code execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation text is broad enough to trigger on common requests about starting a browser or checking browser status, which can cause the skill to run in contexts where the user did not intend to expose a remote desktop, VNC service, or debugging port. Because this skill enables network-accessible browser control, accidental activation has meaningful security and privacy consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation advertises unaudited remote access endpoints for VNC, web VNC, and Chrome DevTools without any warning about authentication, network exposure, or the sensitivity of browser contents. These interfaces can enable full browser control, session hijacking, inspection of tabs and data, and potentially access to authenticated web sessions if reachable by unauthorized parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly instructs operators to open VNC, noVNC, and Chrome DevTools ports to other machines and provides direct access URLs, including a URL pattern that embeds the VNC password in the query string. Exposing Chrome DevTools remotely is particularly dangerous because it can enable full browser control, access to authenticated sessions, and data exfiltration if not tightly restricted.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/configuration.md (reported line 199)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/configuration.md (reported line 200)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/configuration.md (reported line 205)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/configuration.md (reported line 206)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/configuration.md (reported line 207)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 22)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 23)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 28)May include surrounding context.

bash
# Install all dependencies
sudo apt-get update
sudo apt-get install xvfb x11vnc novnc websockify chromium openssl

# Alternative: Use Google Chrome instead of Chromium

Static analysis

No suspicious patterns detected.